Purpose: Work through one cyber-risk scenario from scope to treatment. The worksheet is useful in interviews, workshops, project reviews, supplier reviews, or periodic assessments.
Worksheet prompts
1. ScopeWhich service, process, data set, project, location, or supplier is being assessed?
2. ObjectiveWhat must the organization achieve or protect?
3. ScenarioWhat plausible event could occur, and how could it develop?
4. ConsequenceWhat operational, financial, customer, legal, safety, or strategic effect could follow?
5. Existing safeguardsWhat reduces likelihood, limits consequence, improves detection, or supports recovery?
6. Evidence and confidenceHow do we know those safeguards are working?
7. Inherent and residual assessmentHow does exposure change after safeguards are considered?
8. TreatmentWhat action or acceptance is required, by whom, and when?
9. ReviewWhat date or change will trigger reassessment?
Worked examples
| Example | Context / Rating |
|---|
How to use this page
- Interview the people who operate the process, not only technology staff.
- Distinguish facts from assumptions and open questions.
- Use ranges when duration or cost cannot be known precisely.
- Document conflicting views rather than forcing false agreement.
- End with a named decision owner and review trigger.
Cautions
- A rating without a scenario is difficult to interpret.
- A workshop is not complete until actions and acceptances are recorded.
- Do not hide weak evidence behind precise numeric scores.
Educational use: Tailor the language and decision authority to the organization. This page is not a certification, legal opinion, security assessment or substitute for professional advice.
Frequently asked questions
Can a small organization use this tool?
Yes. Reduce the number of fields or questions, but retain the scenario, business consequence, accountable owner, decision and review date.
Does this replace professional advice?
No. It is an educational structure. Legal, insurance, compliance, cybersecurity and other professional decisions may require qualified advice.
How often should it be updated?
Update it when the related service, supplier, data, threat conditions, controls, incident history or business priorities change materially.